MALICIOUS — CRITICAL
coinomi.ca Safety Check — Brand Impersonation Detected
coinomi[.]
This domain, coinomi.ca, was registered through CENTRALNIC CANADA INC on 29 January 2025.
- VirusTotal
- 15/95
- Blocklists
- No stored match
- Verfügbarkeit
- Inhalt nicht verfügbar · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
coinomi.ca — Inhalt nicht verfügbar (HTTP 502). Markenidentität: Across. Zusammenfassung der Beweislage: VirusTotal 15/95 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, AlphaSOC, BitDefender); PhishDestroy score 95/100. Registrar: CENTRALNIC CANADA.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Evidence Analysis
This domain, coinomi.ca, was registered through CENTRALNIC CANADA INC on 29 January 2025. The authoritative name servers are dns1.icedns.is and dns2.icedns.is, and the zone resolves to IP 87.120.126.41, which belongs to AS215730 (H2NEXUS LTD) and is geolocated in Germany. No TLS certificate is presented, indicating that the site was served over plain HTTP when active. The page title observed in the last crawl reads “Coinomi – Cryptocurrency trading and invest platform,” suggesting an attempt to impersonate the Coinomi brand across multiple services.
Gridinsoft assigned a trust score of 0 / 100, and VirusTotal reports that 15 of 95 scanned security vendors flagged the domain as malicious. The domain appears on a single external blocklist and has been listed by PhishDestroy as a confirmed phishing source. Current probing shows the host is taken offline, but the infrastructure footprint remains visible and could be re‑activated.
Uncertainty remains regarding the exact phishing kit or credential‑harvesting page structure, as no content snapshot is available. Defenders should continue to monitor the IP address 87.120.126.41 for any resurgence, enforce blocklisting of the domain and its IP in perimeter defenses, and update URL filtering rules to include the observed page title pattern. Additional intelligence collection, such as requesting a live HTTP response or examining the associated ASN traffic, is recommended to confirm whether the infrastructure is being reused for other brand‑impersonation campaigns.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Datenabdeckung12 recorded checks
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
VirusTotal-Analyse
Nachweise und externe BerichteIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.